Security
How Reviso protects agent connections, content, and account access — token scope, data access, audit, and how you revoke authorization.
Agent connections and token scope
Agent connections are account-level. An authorized agent can only reach the team spaces and documents the underlying Reviso account can reach, and every MCP call passes the same capability checks the browser uses. A connection never silently grants administrative or other-account access.
- Transport: Streamable HTTP, scoped to the agent connection
- Auth: OAuth 2.1 / PKCE with browser consent
- Local tokens: For headless agents that cannot open a browser; scope equals the account that minted them
Break-glass and account credentials
Owner and bootstrap keys are break-glass management paths only. They are not used to authorize content reads or writes by an account, and an owner key is not accepted as a substitute for a normal connection.
Content access model
Reviso applies the same membership, shared-link, and permission model to agents and humans. Tool visibility is filtered by the capability map of the connection at call time, and every writing tool enforces its route capability independently.
- view — read documents, versions, and structure
- edit_file — propose structured edits and versions
- comment — create, reply, and resolve comment threads
- manage_members — create and revoke invites and share links
- archive_file — archive and restore documents
Audit and provenance
Document edits carry provenance: version history, rollback, comments with anchor evidence, and collaborative-update CRDT rows are content truth. Failed intents are recorded and recoverable rather than silently overwritten.
- Versions: Every agent-authored update cuts a reviewable version
- Rollback: Revert to any prior version in the browser
- Failed writes: Recoverable intents; no silent data loss
Revoking access
Revoke an agent connection or a local token at any time from Settings > Integrations. Revoking removes the saved grant; the client can no longer authenticate without a fresh OAuth consent.
Reporting a vulnerability
Keep security feedback focused on the connection layer, content-access model, and capability enforcement. Report by contacting the maintainers directly before public disclosure.